PT-2017-16375 · Netiq · Netiq Access Manager
Published
2017-04-20
·
Updated
2017-07-11
·
CVE-2017-5190
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NetIQ Access Manager versions 4.2 before SP3 HF1 and 4.3 before SP1 HF1
Description
The issue is related to a concurrency problem that causes information leakage when NetIQ Access Manager is configured as a SAML 2.0 Identity Server with Virtual Attributes. This is due to a stale profile.
Recommendations
For versions 4.2 before SP3 HF1, update to SP3 HF1 or later to resolve the issue.
For versions 4.3 before SP1 HF1, update to SP1 HF1 or later to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Netiq Access Manager